PT-2018-5155 · Unknown · Html-Janitor

Published

2018-06-04

·

Updated

2019-10-09

·

CVE-2017-0928

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions html-janitor versions prior to 2.0.4
Description The issue allows for the bypass of sanitization due to user control of the sanitized variable, leading to cross-site scripting (XSS) attacks. This can occur when arbitrary HTML passes the sanitization process, posing a risk if user-controlled input is passed to the clean function.
Recommendations Upgrade to version 2.0.4 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-0928
GHSA-FX46-WHRJ-73V5

Affected Products

Html-Janitor